[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fAy4dcPVfM45rMReM0l--L7E442p94Exxy477jrhtsfQ":3},{"id":4,"url_slug":5,"title":6,"description":7,"plugin_slug":8,"theme_slug":9,"affected_versions":10,"patched_in_version":11,"severity":12,"cvss_score":13,"cvss_vector":14,"vuln_type":15,"published_date":16,"updated_date":17,"references":18,"days_to_patch":20},"CVE-2022-0770","translate-wordpress-with-gtranslate-translate-wordpress-google-language-translator-missing-authorization-to-sensitive-in","Translate WordPress with GTranslate \u003C= 2.9.8 & Translate WordPress – Google Language Translator \u003C= 6.0.13 - Missing Authorization to Sensitive Information Disclosure","The Translate WordPress with GTranslate \u003C= 2.9.8 &  Translate WordPress – Google Language Translator \u003C= 6.0.13  WordPress plugins do not have proper capabilities checks in the \u002Fwp-content\u002Fplugins\u002Fgtranslate\u002Furl_addon\u002Fgtranslate.php file which writes debug data such as user's cookies in a publicly accessible file when the enable_debug parameter is set to true. This would make it possible for an attacker to steal and administrators cookies if they can successfully trick them into accessing that file with the parameter set.","google-language-translator",null,"\u003C=6.0.13","6.0.14","high",8.8,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:U\u002FC:H\u002FI:H\u002FA:H","Missing Authorization","2022-03-07 00:00:00","2024-01-22 19:56:02",[19],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002Fff21e539-8ba0-4edd-a90c-27a4cd1cdbc7?source=api-prod",687]